SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Suprema BioStation 3 sets global sales record
    • A landmark gathering shaping the future of real estate, investment, sustainability & design
    • IDIS launches new AI PTZ cameras for enhanced security
    • Leuze AI elevates optical sensor precision
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    • How should security adapt to the unique aspects of healthcare?
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Technology Summit International 2025

    Technology Summit International 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    G2E Philippines 2025

    G2E Philippines 2025

    IFSEC India 2025

    IFSEC India 2025

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    One system, one card

    One system, one card

    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

About us Advertise
  • AI-powered video analytics
  • AI special report
  • Cyber security special report
  • 6
Intrusion detection
  • Home
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check out our special report on casino security

Get it now!

NISC survey finds 9 of 10 security leaders believe companies should face consequences for releasing insecure software

1 Nov 2022

NISC survey finds 9 of 10 security leaders believe companies should face consequences for releasing insecure software
Contact company
Contact Vercara, LLC (formerly Neustar Security Services LLC)
icon Add as a preferred source Download PDF version

Organisations plan to invest in DevSecOps in 2023, and the level of urgency for them to do so has grown.

In a recent survey conducted by the Neustar International Security Council (NISC), 93 percent of participating information technology and security professionals reported that DevSecOps would be a significant budgeting priority in 2023, with 55 percent emphasising it would be a very significant priority with their organisation.

Factors to consider

Additionally, 86 percent of respondents agree that the urgency to prioritise DevSecOps has increased within their organisation over the past 12 months.

The top three factors driving this urgency were growing risk driven by accelerating digitisation of their business (60 percent), the proliferation of high-profile supply chain attacks across the industry (53 percent), and an increasingly complex and rigorous regulatory and compliance landscape marked by growing liability for their organisation should customers or partners be put at risk.

Identifying vulnerabilities 

DevSecOps should help better position organisations to identify potential vulnerabilities early"

“DevSecOps has become a high priority for organisations as they look to better establish security as a central tenet through every phase of the software development lifecycle and ensure every release has security baked into the code,” said Carlos Morales, senior vice president of solutions at Neustar Security Services.

“By making security a shared responsibility across development, operations, and security teams, DevSecOps should help better position organisations to identify potential vulnerabilities early in the process ideally before being put into production, and save them from much bigger headaches down the line.”

Insecure software consequences 

Application vulnerabilities can be costly, both in resources allocated to fix security gaps and in revenue should a breach result in lost business and confidence. Among NISC survey participants, 92 percent agreed - 40 percent strongly that companies should face consequences if their software is found to be unsound or insecure.

Many favoured government interventions, with approximately half (51 percent) saying government bodies should force the culprit to implement more rigorous security measures and adopt DevSecOps, while nearly four in ten (38 percent) felt government bodies should punish the offending company with sizable fines.

Software supply chain security controls

A strong proportion of respondents were also in favor of recourse for impacted companies. 50 percent felt the liable party should foot the bill for all mitigation and remediation costs by impacted downstream organisations, while 44 percent said downstream companies or customers relying on the vulnerable software should be able to file suit for damages. 

Moreover, 93 percent of organisations agree that federal mandates for software supply chain security controls are a good idea and should be implemented broadly, and more than one-third (36 percent) feel strongly about the prospect.

Implementing the DevSecOps strategy 

Only 13 percent of surveyed participants confirmed that their organisation has fully implemented its strategy

While more than nine in 10 organisations reside somewhere on the spectrum between building and fully implementing a formal DevSecOps strategy, only 13 percent of surveyed participants confirmed that their organisation has fully implemented its strategy.

Almost one-third (29 percent) are in the process of implementing a strategy, while 15 percent are on the cusp of implementation and 35 percent are still in the process of building a formal strategy.

Drivers of adoption 

Various drivers are contributing to organisations’ adoption of DevSecOps. Nearly three-quarters (72 percent) of respondents identified improving their ability to discover, profile and monitor a growing inventory of applications and APIs through automated processes as one of the three most important drivers of their adoption of DevSecOps.

Other important drivers of adoption include the need for more thorough code monitoring to better detect vulnerabilities throughout development, testing, and operations (64 percent), driving a more robust security-centric culture for the organisation (63 percent), and better compliance monitoring (62 percent).

Factors for delayed DevSecOps adoption 

Despite the growing importance of adopting DevSecOps, a range of factors are holding organisations back from doing so successfully. Chief among them is the shortage of security talent needed to implement the programme, as cited by 42 percent of respondents.

Other factors detracting from efforts include the organisational culture (37 percent), tool incompatibility (36 percent), difficulty in finding a project champion or shared responsibility for the initiative (33 percent), and a lack of buy-in from senior leadership (29 percent).

Security concerns 

System compromise and ransomware followed as top concerns among 20 percent and 17 percent of respondents

In other security concerns, professionals during the reporting period of July and August 2022 remained focused on the potential for DDoS attacks, which were identified by 21 percent as their highest perceived threat. Similar to past survey periods, system compromise and ransomware followed as top concerns among 20 percent and 17 percent of respondents, respectively.

Also similar to last period, ransomware was perceived to be an increasing threat among 75 percent of survey respondents, while generalised phishing jumped in visibility and was on the radar for 74 percent of participants. DDoS attacks, targeted hacking, and social engineering via email were closely followed and reported as increasing by 72 percent, 71 percent, and 70 percent of surveyed professionals, respectively.

DDoS attacks

DDoS attacks continue to be prevalent, and 86 percent of enterprises surveyed indicated that they have been on the receiving end of a DDoS attack at some point, a one-percentage-point increase over the previous survey period.

The majority (56 percent) outsource their DDoS mitigation, and most (62 percent) indicated that mitigation of attacks typically occurred between 60 seconds and 5 minutes, consistent with previous survey findings.

NISC survey 

The NISC survey was conducted in September 2022 and reflects respondents’ activity and concerns during July and August 2022.

The survey enlisted feedback from senior information technology and security professionals from across six EMEA and U.S. markets.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Biometrics
  • Office surveillance
  • Digital video surveillance
  • Office security systems
  • Office security
  • Industrial security
  • Commercial security
  • Security management
  • Security policy
  • Security installation
  • Security tagging
  • Security cameras
  • Security camera systems
  • Security monitoring system
  • Facial recognition systems
  • Network monitoring
  • Video analytics
  • Intrusion detection
  • Identity management
  • Fingerprint reader
  • Industrial security systems
  • Security software
  • Security service
  • Industrial surveillance
  • Integration software
  • Cyber security
  • Crime prevention
  • Crowd Management
  • Corporate Security
  • Indoor Security
  • Data Security
  • Network Video Recorders
  • Digital Video Recorders
  • Incident Management
  • Cloud security
  • Related categories
  • Access control software
  • Digital video recorders (DVRs)
  • CCTV software
  • Access control readers
  • Network video recorders (NVRs)
  • Access control cards/ tags/ fobs
Related white papers
Precision and intelligence: LiDAR's role in modern security ecosystems

Precision and intelligence: LiDAR's role in modern security ecosystems

Download
The top 4 reasons to upgrade physical security with the Cloud

The top 4 reasons to upgrade physical security with the Cloud

Download
11 advantages of a combined system for access control and intrusion

11 advantages of a combined system for access control and intrusion

Download
Related articles
Securitas UK & Hays Travel mark 10 years partnership

Securitas UK & Hays Travel mark 10 years partnership

Ranger acquires Universal Fire & Security in South West

Ranger acquires Universal Fire & Security in South West

Detection Tech's DT2030 strategy: Enhance X-ray detector solutions

Detection Tech's DT2030 strategy: Enhance X-ray detector solutions

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Intrusion detection
  4. News
  5. Corporate news
See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
Addressing Cybersecurity Vulnerabilities in the Physical World
Addressing Cybersecurity Vulnerabilities in the Physical World
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec